neural-hash-collider
owasp-mstg
Our great sponsors
neural-hash-collider | owasp-mstg | |
---|---|---|
37 | 1 | |
651 | 0 | |
- | - | |
1.2 | 10.0 | |
about 1 year ago | almost 2 years ago | |
Python | ||
MIT License | Creative Commons Attribution Share Alike 4.0 |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
neural-hash-collider
- Daily General Discussion - October 27, 2022
- [@tim_cook about privacy] “We believe privacy is a fundamental human right, and the best technology is one that people can trust. At Apple, we’re constantly innovating to give our users more control over how their data is used and the choice with whom to share it.”
- Under pressure from Russian government Google, Apple remove opposition leader's Navalny app from stores as Russian elections begin
-
Apple delays iPhone photo-scanning plan amid fierce backlash
That assumes the hash is base 26 which would be fun, but most hashing systems including NeuralHash are hexadecimal. NeuralHash also outputs 24 character hashes so there are 1624 possible NeuralHashes. However all of that ignores that NeuralHash is designed so that visually similar images will return the same hash on purpose. You can even provide two images of your choosing to this library and it will make them collide https://github.com/anishathalye/neural-hash-collider
-
Delays Aren't Good Enough–Apple Must Abandon Its Surveillance Plans
This is incorrect.
The images in this link [1], are completely different. One is a cat, one is a dog. Same hash produced for both.
[1] https://github.com/anishathalye/neural-hash-collider
- GitHub - anishathalye/neural-hash-collider: Preimage attack against NeuralHash 💣
- The All-Seeing "i": Apple Just Declared War on Your Privacy
-
Tell Apple: Don’t Scan Our Phones
And here: https://github.com/anishathalye/neural-hash-collider
- Apple Just Gave Millions of Users a Reason to Quit Their iPhones
-
Apple Just Gave Millions Of Users A Reason To Quit Their iPhones
Also, Apple’s NeuralHash is rather prone to hash collisions, i.e. false positives, so you should absolutely expect at least some of your on-device pics to be viewed by unauthorized Apple/government personell.
owasp-mstg
-
Google Play rolls out an "Independent security review" badge for apps
I found a more detailed explanation of it: https://github.com/julepka/owasp-mstg/blob/master/Document/0...
> Generally, you should provide compiled code with as little explanation as possible. Some metadata, such as debugging information, line numbers, and descriptive function or method names, make the binary or bytecode easier for the reverse engineer to understand, but these aren't needed in a release build and can therefore be safely omitted without impacting the app's functionality.
I'm not a big fan of the reasoning, as it's security through obscurity. Which is not the worst tradeoff, but these days it just makes public bug bounties (and other public auditing) end up being less of an interesting prospect for improving security.
What are some alternatives?
hardened_malloc - Hardened allocator designed for modern systems. It has integration into Android's Bionic libc and can be used externally with musl and glibc as a dynamic library for use on other Linux-based platforms. It will gain more portability / integration over time.
buildAPKs - Really quickly build APKs on handheld device (smartphone or tablet) in Amazon, Android, Chromebook and Windows📲 See https://buildapks.github.io/docsBuildAPKs/setup to start building APKs.
neuralhash-collisions - A catalog of naturally occurring images whose Apple NeuralHash is identical.
android-udev-rules - Android udev rules list aimed to be the most comprehensive on the net
json - JSON for Modern C++
website - The elementary.io website
harbormaster
reFlutter - Flutter Reverse Engineering Framework
glodroid_manifest - Android port that aims to bring both user- and developer-friendly experience in using AOSP with a set of single-board computers (SBC), phones and other devices.
owasp-masvs - The OWASP MASVS (Mobile Application Security Verification Standard) is the industry standard for mobile app security.
AppleNeuralHash2ONNX - Convert Apple NeuralHash model for CSAM Detection to ONNX.
theos-jailed - A Theos module to develop jailed tweaks for iOS 8 and up